Description
Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows.

This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.
Published: 2026-07-14
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper privilege management in the Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows allows a low‑privileged local user to obtain SYSTEM privileges on the host. The flaw, identified as CWE‑269, permits the attacker to elevate privileges to full system rights. This can potentially enable full control over the affected system, including executing arbitrary code, installing software, or exfiltrating data.

Affected Systems

The vulnerability afflicts Citrix Secure Access Client for Windows versions prior to 26.6.1.20 and Citrix Endpoint Analysis Client for Windows versions prior to 26.5.1.7. Systems running the impacted Windows client software are susceptible, while later releases contain the fix.

Risk and Exploitability

The CVSS score of 8.5 classifies the issue as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: a user who can run the client application with standard privileges can trigger the elevation. This local nature limits exposure to physical or remote users who can access the machine, but once compromised the attacker gains full system rights.

Generated by OpenCVE AI on July 31, 2026 at 10:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Citrix Secure Access Client to version 26.6.1.20 or newer.
  • Upgrade Citrix Endpoint Analysis Client to version 26.5.1.7 or newer.
  • Until the upgrade is deployed, restrict local users from launching the affected client or enforce least‑privilege policies to limit the reach of potential privilege elevation.

Generated by OpenCVE AI on July 31, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.
Title Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Citrix

Published:

Updated: 2026-07-15T04:00:59.472Z

Reserved: 2026-06-09T18:32:47.375Z

Link: CVE-2026-53565

cve-icon Vulnrichment

Updated: 2026-07-14T13:20:55.472Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management